CVE-2025-0911
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 11, 2025
Updated: Feb 12, 2025
CWE ID 125
Summary
CVE-2025-0911 is an Information Disclosure vulnerability in PDF-XChange Editor's U3D file parsing process. This issue allows remote attackers to read sensitive information from affected installations by manipulating U3D files. The vulnerability arises due to insufficient data validation, leading to an Out-Of-Bounds Read. An attacker could combine this flaw with other vulnerabilities to execute arbitrary code. User interaction, such as visiting a malicious webpage or opening a malicious file, is required to exploit this issue. (ZDI-CAN-25957)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- PDF-XChange Editor